A VARA licence application under heightened scrutiny (the review track that Dubai's Virtual Assets Regulatory Authority applies when a proposed activity carries elevated risk) is not a standard regulatory checkbox. It is a full-spectrum examination of governance, financial resilience, AML/CFT posture and cross-border exposure – conducted before a single transaction is cleared through a licensed platform. Operators who underestimate the depth of that examination routinely stall for months, lose banking relationships in the interim, or receive outright refusals that damage their prospects across every other licensing pipeline.
This page sets out the regulated basis, the application architecture, the common failure points we have mapped in practice, and a decision matrix for the profiles most likely to face VARA's heightened scrutiny track. The cross-border dimension – where your users sit, where your banking clears and how VARA's regime intersects with MiCA or MAS obligations – runs through every section.
What is the regulated basis for VARA licensing in Dubai?
VARA operates as Dubai's dedicated virtual-asset regulator for mainland Dubai – distinct from the DIFC financial free zone, which runs its own FSRA-supervised regime. Under the VARA regime, any entity wishing to conduct virtual-asset activities in or from Dubai must hold an activity-specific licence. VARA's activity-based architecture means the licence is not a single instrument: it is a bundle of approvals tied to each regulated activity – advisory, broker-dealer, custody, exchange services, lending, management and investment, and transfer/settlement. A business offering exchange and custody together must qualify under both activity rulesets.
Heightened scrutiny is not a separately named licence category. It is the review posture VARA adopts when a proposed business model triggers elevated-risk indicators. Those indicators include exchange or lending activities, cross-border user bases, proprietary token issuance linked to the platform, custody of client assets, or complex group structures spanning multiple jurisdictions. In our licensing practice, nearly every exchange-custody hybrid and every platform with a non-UAE user majority enters the application under this posture by default.
The applicable VARA rulebooks – the Company Rulebook, the Compliance and Risk Management Rulebook, and the activity-specific rulebook for each licensed function – set the substantive standards. VARA does not operate a light-touch registration track for the activities most operators want to run. The regime was designed to be credible to institutional counterparties and correspondent banks, and the scrutiny level reflects that ambition.
Operators we advise consistently note that the gap between a preliminary approval and a full operational licence is wider under VARA than under comparable regimes in Singapore or Malta. Understanding that gap – and building the governance infrastructure to close it – is the central challenge of the engagement.
Who needs a VARA licence – and does heightened scrutiny apply to your model?
Any business conducting a regulated virtual-asset activity in or from mainland Dubai requires a VARA licence, regardless of where it is incorporated. A foreign entity operating a platform accessible to UAE users without local authorisation is in scope. The territorial test turns on where the activity is conducted and where the client is located, not on where the legal entity is registered.
Heightened scrutiny typically applies to the following operator profiles.
- Centralised exchanges offering spot or derivatives trading to retail or institutional users, particularly where the platform holds client assets rather than operating a pure non-custodial model.
- Custodians holding digital assets under a discretionary or fiduciary mandate, where the safeguarding and segregation obligations under VARA's Custody Activity rulebook attract the deepest governance examination.
- Lending and yield platforms, which VARA treats as carrying systemic risk potential and therefore subjects to more granular stress-testing and collateral-management analysis.
- Multi-activity groups seeking to run exchange, custody and transfer/settlement under one UAE structure – a common ambition, and the configuration that most reliably triggers the full scrutiny posture.
- Token issuers whose issued asset is also traded on a VARA-licensed platform in which they have an ownership or control interest.
A business operating only an advisory or management-and-investment function for sophisticated counterparties may face a lighter review path. But in our cross-border practice, the majority of inbound operators to Dubai are not in that category. They are building exchange-led or custody-led infrastructure, and the application path they face is the heightened one.
What does the VARA application process actually look like?
The VARA application process under heightened scrutiny runs in structured stages, each with its own documentary burden and VARA engagement cadence. The total elapsed time from submission of a complete initial package to receipt of a full operational licence varies considerably based on complexity – treat it as a matter of many months rather than weeks, and build your operational runway accordingly.
Stage one is the in-principle or preliminary review. VARA assesses the business model, the proposed activities, the group structure and the initial governance design. The submission at this stage includes a detailed business plan, a high-level risk framework, organisational charts, shareholder and beneficial-owner declarations, and a description of the technology stack. VARA may issue information requests at this stage; response turnaround directly affects timeline.
Stage two is the detailed authorisation review. This is where the scrutiny is heaviest. VARA examines the full compliance programme – AML/CFT policies, the Travel Rule implementation plan, transaction monitoring architecture, sanctions screening, and the customer due-diligence framework. Governance documentation is assessed in depth: board composition, the fit-and-proper assessment of senior management and approved persons, and the adequacy of the risk and compliance functions relative to the proposed activity scale.
Stage three is the capital and financial review. VARA requires evidence that the entity meets the applicable minimum capital requirement for each licensed activity and can demonstrate financial resilience over the projection period. The specific capital thresholds vary by activity category and are set out in the applicable VARA rulebook provisions – figures in this area carry [VERIFY] status in our registry and are stated qualitatively here. What the practitioner needs to know is that the quantum is material, the liquid-asset composition matters, and VARA will examine both the source of the capital and its sustainability under stress.
Stage four is the operational readiness assessment. Before granting a full operational licence, VARA confirms that the technology, custody arrangements, business-continuity plan and client-onboarding infrastructure are actually in place and functioning – not merely described in a policy document. This stage is frequently underestimated by first-time applicants.
A micro-matter from our recent practice illustrates the timeline risk. In a recent engagement, a mid-size exchange group with existing licences in a leading EU jurisdiction sought a VARA exchange-and-custody licence ahead of a scheduled Dubai office launch. The group's compliance team had mapped its MiCA-compliant programme to the VARA requirements and assumed substantial equivalence. VARA's review identified gaps in the Travel Rule implementation architecture for VASP-to-VASP transfers involving non-licensed counterparties, and the custody segregation model did not meet the activity-specific rulebook standard. We restructured the compliance programme, produced a revised segregation matrix and coordinated the fit-and-proper submissions for two additional approved persons. The in-principle approval followed in the next review cycle. The lesson: prior regulatory authorisation in another jurisdiction provides credibility, not equivalence.
To map your application timeline against your operational plans, contact OBOLUS at info@oboluslaw.com. The process above describes the standard path. Your entity structure, your user base and your existing licensing stack change the analysis materially.
What are the most common mistakes in a VARA licence application?
The failure points we see most consistently in heightened-scrutiny VARA applications share a common theme: the applicant managed a compliance documentation exercise rather than a regulatory authorisation process. The distinction matters because VARA's review is substantive, not formal. A policy document that looks complete on its face will not survive a line-by-line interrogation if the underlying framework is not operationally real.
The most consequential mistakes, in order of frequency in our practice:
- Incomplete beneficial ownership disclosure. VARA requires disclosure of the full beneficial ownership chain, including ultimate beneficial owners above the applicable threshold, any person exercising significant influence, and the source of the capital being injected into the entity. Gaps at this stage reliably produce information requests that extend the timeline by weeks.
- Under-resourced compliance function. VARA expects the compliance officer to be a full-time, Dubai-based approved person with demonstrable virtual-asset experience. An arrangement where the compliance function is outsourced entirely to a third-party provider, or where the MLRO is employed by a parent entity in another jurisdiction, will not satisfy the standard under the Compliance and Risk Management Rulebook.
- Travel Rule architecture not matched to the activity. The Travel Rule (the obligation to transmit originator and beneficiary data with a virtual-asset transfer) requires a technical solution – not merely a policy describing how the business intends to comply. VARA's review will probe the actual protocol and counterparty coverage. Platforms that have only partial VASP coverage in their Travel Rule solution – a common reality for new entrants – must address this before the detailed review stage or face a material deficiency finding.
- Technology documentation that describes the target state, not the current state. Applicants frequently submit technology architecture documents that reflect the intended end-state of the platform rather than the version that will be operational on licence grant. VARA assesses what exists, not what is planned.
- Governance structures that do not reflect the activity scale. A board of two directors with no independent non-executive is not adequate governance for a custody business holding material third-party assets. VARA's expectation around independent oversight, audit-committee-equivalent functions and documented conflict-of-interest management scales with the activity risk profile.
Each of these failure points is remediable. None of them is a reason to abandon a well-structured application. But they each require identification before submission, not after an information request lands.
How does the VARA regime interact with your cross-border obligations?
Operating a VARA-licensed business from Dubai does not insulate you from the regulatory obligations of the jurisdictions where your users are located. This is the point where operators most frequently hold a mistaken assumption – and it is worth addressing directly.
A VARA licence authorises you to conduct virtual-asset activities in or from mainland Dubai. It does not passport you into the EU, into Singapore, into the UK or into any other jurisdiction. If your platform is accessible to users in those markets, you are subject to the local regime: MiCA for EU-resident users, the MAS Payment Services Act framework for Singapore, the FCA's registration and financial-promotion rules for the UK. In the EU, the mandatory MiCA CASP authorisation applies to any entity providing crypto-asset services to EU clients – VARA authorisation is not a substitute.
The cross-border exposure runs in the other direction as well. If your group holds a MiCA CASP authorisation in Lithuania or Malta, you cannot simply use that entity to serve the UAE market without VARA authorisation for the Dubai-facing activity. ESMA and VARA operate on the same territorial logic from opposite ends.
Banking is the third dimension. A VARA-licensed entity in Dubai still requires correspondent banking relationships, and the banks that service virtual-asset businesses in the UAE have their own compliance requirements – frequently including evidence of VARA authorisation, a clean AML programme and a client-base risk assessment. In our cross-border practice, we have seen operators obtain a VARA licence in principle and then spend additional months resolving banking before going operational. The licence and the banking stack need to be built in parallel, not sequentially.
For structures involving EU or UK users, we work alongside allied counsel in the relevant jurisdiction to map the full multi-licence architecture before the VARA application is submitted. The application itself is stronger when the applicant can demonstrate a coherent multi-jurisdiction compliance design, rather than treating Dubai as a standalone.
Which operator profile should pursue a VARA licence – and under what conditions?
Not every business targeting the MENA region should anchor its licensing strategy in Dubai under VARA. The right answer depends on the activity, the user base and the capital position of the business.
Profile A – Exchange operator targeting Gulf institutional and retail users. This is the natural VARA use case. The regime was designed for this activity profile. The exchange activity rulebook is mature, the regulator has cleared institutional applicants, and a VARA-licensed exchange carries credibility with Gulf institutional counterparties and family offices that lighter registrations do not. The timeline is long and the governance investment is real. Capital commitment must be material and liquid. The operator who should proceed: one with a proven governance team, a functioning compliance infrastructure that can be adapted to the VARA standard, and banking already identified or in process. The operator who should wait: one that is pre-revenue, under-capitalised or relying on a two-person compliance function.
Profile B – Custody-first operator seeking Gulf institutional mandates. The VARA custody activity is a strong fit for a business whose primary revenue is safeguarding rather than trading. The custody rulebook's requirements around segregation, technology controls and insurance are demanding, but they align with what institutional clients expect from a licensed custodian. The key risk is the governance intensity: an approved-person list for a custody business will be longer than for a lighter-touch activity, and each person faces a fit-and-proper review. Timeline to operational licence for this profile is typically at the longer end of the range.
Profile C – Multi-activity group (exchange + custody + transfer/settlement). This is the highest-scrutiny profile. The application covers multiple activity rulesets simultaneously, the capital requirement aggregates across activities, and the compliance function must be resourced to cover the full perimeter. This profile makes commercial sense for a well-capitalised operator building a complete institutional infrastructure. It does not make sense as an initial licence application for an early-stage business. The right sequencing is typically to apply for the exchange activity first, demonstrate operational competence, and extend the licence scope as the business matures.
Profile D – Token issuer with platform exposure. If the issuer also operates or has a controlling interest in a VARA-licensed exchange, VARA will examine the conflict-of-interest management between the issuance function and the trading function with particular care. The application can succeed, but the governance documentation – board-level conflict management, trading-desk separation, and market-integrity controls – needs to address the concern directly and in advance of the review.
If a prior application stalled or your banking was closed after a VARA submission, a second read of the application and the response history can surface the structural reason. Contact OBOLUS at info@oboluslaw.com to map the route back.
A common assumption: is a single offshore licence enough?
A common assumption among first-time applicants is that a single offshore registration – a BVI VASP Act registration, a Cayman CIMA licence, or an entity incorporated in a low-friction jurisdiction – provides sufficient regulatory cover to serve clients globally, including in the UAE. That assumption is incorrect, and acting on it is one of the faster routes to enforcement exposure.
Offshore registrations serve specific purposes: they are appropriate for fund structures, for entities with a genuinely limited and defined activity scope, and for holding vehicles. They do not substitute for a VARA licence if the activity is being conducted in or from Dubai, and they do not substitute for a MiCA CASP authorisation if EU clients are being served. The BVI FSC's VASP Act 2022 and CIMA's VASP Act regime govern activities within those jurisdictions and provide a compliance baseline for entities incorporated there – not a global licence.
The consequence of operating under this misapprehension is not theoretical. VARA has demonstrated its willingness to take action against entities conducting regulated virtual-asset activities in Dubai without authorisation. The risk is enforcement, loss of banking relationships and reputational damage that affects every subsequent licensing application.
Mapping the licence stack properly – across the operating entity, the custody layer and the payment-processing infrastructure – before committing to a business model is the correct approach. It is the approach we take at the outset of every engagement.
Self-assessment: is your application ready for VARA's heightened review?
Before submitting a VARA application, a business in the exchange-custody-lending category should be able to answer yes to each of the following questions. These are not exhaustive – they are the minimum threshold questions that, when answered no, reliably produce a deficiency finding or an information request.
- Does the entity have a full-time, Dubai-based compliance officer and MLRO who is a VARA-proposed approved person?
- Is the beneficial ownership chain documented to the ultimate level, with source-of-funds evidence for the capital being injected?
- Does the AML/CFT programme address the specific risks of the proposed activity – including the Travel Rule protocol for the counterparty types the business will transact with?
- Is the technology architecture documented as it currently exists, not as it is planned to exist at a future date?
- Does the custody model, if custody is a proposed activity, meet the segregation and safeguarding standards in the applicable VARA rulebook?
- Has the board composition been reviewed against VARA's governance expectations for the activity profile and asset scale?
- Is there an identified banking partner willing to operate the account for a VARA applicant, and has the account-opening process begun?
- Has the multi-jurisdiction licence exposure been assessed – specifically, which other regulators have jurisdiction over the proposed user base?
An honest no to any of these questions is a remediation item, not a reason to delay engagement with the process. The remediation is faster when it is identified before submission than after a VARA information request arrives.
Related at OBOLUS
- Licensing & Registration for Digital-Asset Businesses – our practice overview across 70+ licensing jurisdictions, activity categories and regulatory regimes.
- Crypto Exchange Licensing for Early-Stage Founders – a practical guide to licence strategy for founders building exchange infrastructure before a full institutional launch.
- Security Token Offering Structuring in Liechtenstein – how Liechtenstein's token law framework applies to security token issuance and the cross-border structuring considerations.
FAQ
How long does a crypto licence take to obtain?
Timeline varies substantially by jurisdiction and activity category. A VARA licence under heightened scrutiny involves multiple staged reviews and takes many months from a complete initial submission to full operational authorisation. MiCA CASP authorisation in an EU member state follows a defined statutory review period, though pre-submission preparation typically adds to the overall elapsed time. We map expected timelines to each regime at the outset of an engagement, factoring in the specific activity profile and the readiness of the applicant's documentation.
Which jurisdiction is best for licensing my crypto business?
There is no universally best jurisdiction. The right answer depends on where your users are located, which activities you are conducting, your capital position and your banking strategy. Dubai under VARA suits exchange and custody operators targeting Gulf institutional markets. EU member states under MiCA suit businesses needing EU passporting. Singapore under MAS suits operators with an Asia-Pacific focus. In our licensing practice, we build a jurisdiction matrix against the operator's actual profile before recommending a primary domicile – because a well-chosen licence in the wrong jurisdiction for your user base creates more compliance cost than it resolves.
Do I need a separate custody licence?
In most leading regimes – VARA, MiCA, MAS, SFC – custody is a separately regulated activity. Holding client virtual assets under a trading or exchange licence alone is not sufficient. VARA's Custody Activity rulebook imposes specific governance, segregation and technology-control requirements that are distinct from the exchange activity standards. If your business model involves holding client assets, even as an ancillary function to a primary trading activity, the custody licensing question must be addressed at the application design stage, not after the primary licence is granted.
OBOLUS is an independent digital-asset law boutique acting only for businesses. We advise exchanges, custodians, token issuers and funds on licensing across 70+ jurisdictions, on disputes and on-chain asset recovery across 25+ forums, and on the tax, banking and compliance that sit around them. We map the licence stack across operating, custody and payment layers before you commit, so the structure you build is the structure that clears regulatory review. Digital assets are the whole of our practice. To discuss your situation, contact info@oboluslaw.com or message us via t.me/oboluslaw.
By Aisha Tan, Licensing & Jurisdictions Analyst – specialises in activity-based VASP licensing strategy across the Gulf, EU and Asia-Pacific regimes, with a focus on multi-jurisdiction licence architecture for exchange and custody operators.
This publication is general information about the law and does not constitute legal advice. It is not a substitute for advice tailored to your circumstances. OBOLUS accepts no liability for action taken or not taken on the basis of this material. For advice on your situation, contact info@oboluslaw.com.